Junglewise Threat Intelligence

CVE-2025-36076: IBM Cognos Analytics sensitive information exposure in source code

CVE-2025-36076 · Severity: medium · CVSS 4.3 · Published 2026-09-18

Technologies: IBM Cognos Analytics. Vendors: IBM.

Executive brief

IBM Cognos Analytics, a business intelligence platform used for data analysis and reporting, stores sensitive information in its source code. An authenticated attacker with access to the system could extract this sensitive data and leverage it to conduct further attacks, such as credential theft or system compromise.

Technical details

This vulnerability involves improper storage of sensitive information (such as credentials, API keys, or connection strings) in the source code of IBM Cognos Analytics. The flaw affects versions 12.0.4 through 12.0.4 FP2 and 12.1.0 through 12.1.3 FP1. An authenticated user with access to the system's source code or compiled application files can discover and extract this sensitive data. The attack requires valid credentials to access the affected system (authentication required). By obtaining this exposed information, an attacker can escalate privileges, compromise backend systems, or launch secondary attacks against connected infrastructure. Patches have been released in later maintenance levels.

Affected products

  • IBM Cognos Analytics 12.0.4 through 12.0.4 FP2, 12.1.0 through 12.1.3 FP1

Timeline

  • 2026-09-18: disclosed

References

Related threats